Saturday, December 17, 2022

Short Takes – 12-17-22

White House preps security controls for commercial software. FCW.com article. Rules for SBOM and software attestation – Pull quote: “The White House announcement on software acquisition comes as the clock is ticking on key portions of the cybersecurity executive order. Agencies have until September 2023 to collect letters of attestation from vendors to assert that third-party software is compliant with secure software development practices. Agencies must secure letters of attestation by June 2023 for critical software, which NIST defines as software with direct or privileged access to networking or computing resources or otherwise performing functions critical to trust.”

The ‘unprecedented’ risks facing our power grid this winter should be a wake-up call for government. UtilityDive.com article. Pull quote: “NERC’s sobering report is not the first wake-up call regulators and legislators have heard, but it should be the most concerning. Lawmakers should take note before they begin to face capacity shortfalls across the country. One of the most important, cost-effective, and easiest things they can do is fill the forthcoming vacancy at FERC with someone who understands that supporting the energy transition and ensuring the grid has adequate access to dispatchable power throughout the year are not mutually exclusive goals. We can do both by taking a holistic approach, and indeed must do so or risk disastrous consequences.”

Passkeys. WHMurray.Blogspot.com post. Pull quote: “Most often, and at least in the short run, apps that implement Passkeys will  leave their use at the option of the user.  It will be offered as an option, either at enrollment time or when signing on.   If one accesses an account from multiple devices, one  may create a passkey for the account on multiple devices.  Apple plans to store keys in the cloud, as does now with passwords, so that one key can be used across multiple Apple devices sharing access to one Apple account.”

Artemis 1’s Orion capsule returned safely to Earth. What’s next? ScienceNews.org article. Includes overview of activities during the mission. Pull quote: “To prep for Artemis II, “the next step is adding the crew and adding an environmental control and life support system to the Artemis II spacecraft,” Korth says. Several components of the Space Launch System rocket that will launch that next flight are being constructed, and the next Orion crew and service modules are being tested and completed at Kennedy Space Center.”

FBI warns that BEC attacks now also target food shipments. BleepingComputer.com article. Pull quote: “As the FBI, the Food and Drug Administration Office of Criminal Investigations (FDA OCI), and the U.S. Department of Agriculture (USDA) revealed, the value of the stolen food reaches, in some cases, hundreds of thousands of dollars.” FBI Report link - https://www.ic3.gov/Media/News/2022/221216.pdf

EPA Sends State Water Cybersecurity Memo to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from the EPA a “Memorandum to State Drinking Water Administrators on Public Water System Cybersecurity”. This is not listed in the 2022 Spring Unified Agenda, so there is no specific information about what such a memorandum would contain.

Looking at various existing EPA websites relating to State supervision of local drinking water systems cybersecurity issues (see here and here), we can get a general idea of what types of actions the EPA could expect States to “require”:

• Inventory of control system assets,

• Network segregation and firewalls,

• Secure remote access technology,

• Access control and system logs,

• Vulnerability patch policy,

• Mobile device security policy,

• Cybersecurity training program,

• Management involvement, and

• Network intrusion detection and response plan

It is important to note that the EPA, for all but one or two States, has authorized State programs to supervise the local water treatment facilities, so as a practical matter, State agencies would be expected exercise cybersecurity oversight. Changing that State oversight would probably require legislative changes.

CRS Reports – 1st Day of the 118th Congress - House

This week, the Congressional Research Service (CRS) updated their report on “The First Day of a New Congress: A Guide to Proceedings on the House Floor. The publication provides an overview of the formalized activities of the a new Congress that takes office in January of every odd numbered year, typically on January 3rd. Generally, this is expected to be a carefully scripted political theater designed to demonstrate the peaceful transition of power.

Every once in a while (long-while, thankfully), something happens to throw a monkey wrench into the works and upset the smooth flow of gentile politics, and that may happen next month. If you have been following my “Short Takes” blog posts, you will have seen frequent links to articles about the possibility that the House will not be able to elect a Speaker on the first ballot in the 118th Congress because a small number of Republicans want to have more power than their numbers justify. Depending on how strong their egos are (or how much it takes to buy them off), repetitive votes on the Speaker could continue on into the night, perhaps (probably not) days.

What is clear from this CRS report is that operations in the House for the 188th Congress cannot proceed until a Speaker is elected. January could end up being a long, cold, and rancorous month.


Review – Public ICS Disclosures – Week of 12-10-22 – Part 1

On this Saturday after Cyber Tuesday, for Part 1 we have nineteen vendor disclosures from Aruba Networks, Contec, Eaton, Festo, FortiGuard Labs, GE Gas Power, Hitachi Energy (4), HP (7), IFM Electronic, and Phoenix Contact.

Vendor Disclosures

Aruba Advisory - Aruba published an advisory that describes thirteen vulnerabilities in their EdgeConnect Enterprise Orchestrator.

CONTEC Advisory - JPCERT published an advisory that describes four vulnerabilities in the CONTEC SolarView Compact. CONTEC has new versions that mitigate the vulnerabilities.

Eaton Advisory - Eaton published an advisory that describes two vulnerabilities in their Intelligent Power Protector (IPP) software.

Festo Advisory - CERT-VDE published an advisory that discusses a link following vulnerability in multiple Festo products.

FortiGuard Advisory - FortiGuard published an advisory that describes a heap-based buffer overflow vulnerability in their FortiOS SSL-VPN.

GE Gas Power - GE published an advisory that discusses two vulnerabilities in FortiOS.

Hitachi Energy Advisory #1 - Hitachi published an advisory that describes five vulnerabilities in their UNEM Product.

Hitachi Energy Advisory #2 - Hitachi published an advisory that describes five vulnerabilities in their FOXMAN-UN Product.

Hitachi Energy Advisory #3 - Hitachi published an advisory that discusses three vulnerabilities in their Lumada Asset Performance Management (APM) Product.

Hitachi Energy Advisory #4 - Hitachi published an advisory that describes an access control vulnerability in their Lumada APM Product. Hitachi

HP Advisory #1 - HP published an advisory that describes five vulnerabilities (one third-party) in their Security Manager product.

HP Advisory #2 - HP published an advisory that discusses five vulnerabilities in their AMD Client UEFI Firmware.

HP Advisory #3 - HP published an advisory that describes a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in their PC BIOS.

HP Advisory #4 - HP published an advisory that discusses an improper restriction of operations within  the bounds of a memory buffer vulnerability in a wide variety of their PCs.

HP Advisory #5 - HP published an advisory that discusses the Text4Shell vulnerability in their Teradici Cloud Access Connector.

HP Advisory #6 - HP published an advisory that describes a privilege escalation vulnerability in their HyperX NGENUITY software.

HP Advisory #7 - HP published an advisory that describes a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in their AMI UEFI Firmware.

IFM Advisory - CERT-VDE published an advisory that describes a weak password recovery vulnerability in the IFM moneo appliance.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in their PROFINET SDK product.

 

For more information on these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-9ea - subscription required.

Friday, December 16, 2022

Senate Passes Revised HR 7776 – 2023 NDAA

Yesterday, the Senate completed action on the House Amendment to HR 7776, the vehicle for the FY 2023 National Defense Authorization Act. After rejecting a Republican amendment, the Senate voted to concur with the House amendment to the Senate Amendment to HR 7776 by a bipartisan vote of 83 to 11. As in the House vote the Nay votes were also bipartisan (6 Democrats and 5 Republicans). The bill, as amended in the House, includes a variety of cybersecurity provisions that have been discussed elsewhere.

The amendment considered yesterday was SA 6526, proposed by Sen Johnson (R,WI). It would have added a new §525A, Remedies for members of the armed forces discharged or subject to punishment under the covid–19 vaccine mandate. The amendment failed by a vote of  40 to 54, four Republicans joined the Democrats and six Republicans did not vote. The vote required 60 votes to pass, so it was not close.

Nine additional amendments to HR 7776 were proposed yesterday, none of them of any interest here.

The bill now goes to the President for signature, probably next week.


Bills Introduced – 12-15-22

Yesterday, with both the House and Senate in lame duck session, there were 76 bills introduced. One of those bills may see additional coverage in this blog:

HR 9568 To direct the Attorney General to establish a grant program for certain State and local forensic activities, and for other purposes. Armstrong, Kelly [Rep.-R-ND-At Large] 

I will be watching this bill for language and definitions that would include cyber forensics within the scope of the bill.


Review – 20 Advisories Published – 12-15-22

Yesterday, CISA’s NCCIC-ICS published twenty control system security updates for products from Siemens.

PROFINET Update #1 - This update provides additional information on an advisory that was originally published on October 10th, 2019 and most recently updated on October 14th, 2021.

PROFINET Update #2 - This update provides additional information on an advisory that was originally published on April 14th, 2022 and most recently updated on October 13th, 2022.

KTK Update - This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on June 16th, 2022.

Industrial Products Update #1 - This update provides additional information on an advisory that was originally published on May 12th, 2022 and most recently updated on August 11th, 2022.

Industrial Products Update #2 - This update provides additional information on an advisory that was originally published on August 10th, 2021 and most recently updated on September 15th, 2022.

SCALANCE Update - This update provides additional information on an advisory that was originally published on June 12th, 2018 and most recently updated on January 14th, 2020.

SIMATIC Update #1 - This update provides additional information on an advisory that was originally published on April 14th, 2020.

SIMATIC Update #2 - This update provides additional information on an advisory that that was originally published on July 9th, 2020 and most recently updated on April 14th, 2022.

Industrial PCs Update - This update provides additional information on an advisory that was originally published on May 12th, 2022.

OpenSSL Update - This update provides additional information on an advisory that that was originally published on June 16th, 2022 and most recently updated on October 13th, 2022.

Web Server Update - This update provides additional information on an advisory that was originally published on November 10th, 2022.

Teamcenter Update - This update provides additional information on an advisory that originally published on November 10th, 2022.

Nucleus RTOS Update - This update provides additional information on an advisory that was originally published on October 13th, 2022.

Mendix Update - This update provides additional information on an advisory that was originally published on September 15th, 2022 and most recently updated on November 10th, 2022.

SCALANCE Update #1 - This update provides additional information on an advisory that was originally published on October 13th, 2022 and most recently updated on November 10th, 2022.

SCALANCE Update #2 - This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on April 13th, 2022.

SCALANCE Update #3 - This update provides additional information on an advisory that was originally published on January 14th, 2020 and most recently updated on February 11th, 2022.

SCALANCE Update #4 - This update provides additional information on an advisory that originally published on January 12th, 2021 and most recently updated on February 9th, 2021.

SICAM Update - This update provides additional information on an advisory that was originally published on October14th, 2022.

RUGGEDCOM Update - This update provides additional information on an advisory that was originally published on March 10th, 2022 and most recently updated on November 10th, 2022.

 

For more details on these updates, including brief summary of changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/20-advisories-published-12-15-22 - subscription required.


 
/* Use this with templates/template-twocol.html */